Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2017-12136

около 9 лет назад

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2017-12135

около 9 лет назад

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2017-12134

около 9 лет назад

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-12133

больше 9 лет назад

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2017-12132

больше 9 лет назад

The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.

CVSS3: 3
EPSS: Низкий
redhat логотип

CVE-2017-11883

почти 9 лет назад

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly handling web requests, aka ".NET CORE Denial Of Service Vulnerability".

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-11770

почти 9 лет назад

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2017-11755

около 9 лет назад

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an AcquireSemaphoreInfo call.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-11754

около 9 лет назад

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-11753

около 9 лет назад

The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted Flexible Image Transport System (FITS) file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-11752

около 9 лет назад

The ReadMAGICKImage function in coders/magick.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-11751

около 9 лет назад

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-11750

около 9 лет назад

The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-11724

около 9 лет назад

The ReadMATImage function in coders/mat.c in ImageMagick through 6.9.9-3 and 7.x through 7.0.6-3 has memory leaks involving the quantum_info and clone_info data structures.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-11720

больше 11 лет назад

There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-11714

около 9 лет назад

psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2017-11698

около 9 лет назад

Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-11697

около 9 лет назад

The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-11696

около 9 лет назад

Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-11695

около 9 лет назад

Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-12136

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

CVSS3: 9.1
0%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12135

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

CVSS3: 8
0%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12134

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

CVSS3: 7.5
0%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12133

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

CVSS3: 3.7
2%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-12132

The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.

CVSS3: 3
2%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-11883

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly handling web requests, aka ".NET CORE Denial Of Service Vulnerability".

CVSS3: 7.5
9%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-11770

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".

CVSS3: 5.9
5%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-11755

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an AcquireSemaphoreInfo call.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11754

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11753

The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted Flexible Image Transport System (FITS) file.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11752

The ReadMAGICKImage function in coders/magick.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11751

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11750

The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS3: 5.5
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11724

The ReadMATImage function in coders/mat.c in ImageMagick through 6.9.9-3 and 7.x through 7.0.6-3 has memory leaks involving the quantum_info and clone_info data structures.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11720

There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.

CVSS3: 3.3
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2017-11714

psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c.

CVSS3: 4
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11698

Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11697

The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11696

Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-11695

Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

CVSS3: 7.5
1%
Низкий
около 9 лет назад

Уязвимостей на страницу